5.8

CVE-2013-2458

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via "an error related to method handles."

Data is provided by the National Vulnerability Database (NVD)
OracleJre Updateupdate21 Version <= 1.7.0
OracleJre Version1.7.0
OracleJre Version1.7.0 Updateupdate1
OracleJre Version1.7.0 Updateupdate10
OracleJre Version1.7.0 Updateupdate11
OracleJre Version1.7.0 Updateupdate13
OracleJre Version1.7.0 Updateupdate15
OracleJre Version1.7.0 Updateupdate17
OracleJre Version1.7.0 Updateupdate2
OracleJre Version1.7.0 Updateupdate3
OracleJre Version1.7.0 Updateupdate4
OracleJre Version1.7.0 Updateupdate5
OracleJre Version1.7.0 Updateupdate6
OracleJre Version1.7.0 Updateupdate7
OracleJre Version1.7.0 Updateupdate9
OracleJdk Updateupdate21 Version <= 1.7.0
OracleJdk Version1.7.0
OracleJdk Version1.7.0 Updateupdate1
OracleJdk Version1.7.0 Updateupdate10
OracleJdk Version1.7.0 Updateupdate11
OracleJdk Version1.7.0 Updateupdate13
OracleJdk Version1.7.0 Updateupdate15
OracleJdk Version1.7.0 Updateupdate17
OracleJdk Version1.7.0 Updateupdate2
OracleJdk Version1.7.0 Updateupdate3
OracleJdk Version1.7.0 Updateupdate4
OracleJdk Version1.7.0 Updateupdate5
OracleJdk Version1.7.0 Updateupdate6
OracleJdk Version1.7.0 Updateupdate7
OracleJdk Version1.7.0 Updateupdate9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 12.22% 0.932
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N